Skip to content

Security Headers Analyzer MCP tool

MCP findutils:security_headers_analyzer

Grade a set of HTTP response headers for security: returns a 0-100 score, a letter grade (A+ to F), a pass/fail/warning summary, and a per-header finding with a recommendation for CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin-* headers. Pass the headers you already have; this tool does not fetch the URL.

Arguments

application/json
  • headers

    object required

    Response headers as an object of header name → value (case-insensitive), e.g. {"content-security-policy": "default-src 'self'"}. A raw "Name: value" block string (one header per line, as copied from curl -I) is also accepted.

  • url

    string optional

    Optional URL the headers came from. Echoed in the result only.

Example arguments

Verified
{
  "headers": {
    "content-security-policy": "default-src 'self'",
    "strict-transport-security": "max-age=31536000",
    "x-content-type-options": "nosniff",
    "x-frame-options": "DENY"
  },
  "url": "https://example.com"
}